From: Daniel Turull <[email protected]> Record each package's release date in the releaseTime property of its software_Package object, using the SOURCE_DATE_EPOCH already computed for reproducible builds.
Accuracy depends on how SOURCE_DATE_EPOCH was derived: exact for git-tagged recipes, best-effort for tarball/http(s) sources. Some Python sdists (e.g. cryptography, hypothesis, maturin) normalize all file mtimes to a fixed placeholder, so their releaseTime reflects packaging-tool behavior, not the real release date. AI-Generated: Uses Kiro with Claude Sonnet 5 Signed-off-by: Daniel Turull <[email protected]> --- v2: - Dropped all options per Joshua's feedback; read SDE_FILE directly. - Dropped the redundant else: delattr(recipe, "releaseTime") branch. - Selftest compares against SDE_FILE content directly instead of SOURCE_DATE_EPOCH, which can diverge from it. - Fixed a leak: recipes with no git checkout and no fetched source had SDE_FILE holding only SOURCE_DATE_EPOCH_FALLBACK, showing a bogus 2011-04-05T23:00:00Z releaseTime instead of none. v3: - Also run after do_unpack: do_deploy_source_date_epoch's setscene shortcut can skip it, leaving SOURCE_DATE_EPOCH unset. - get_release_date() reads SOURCE_DATE_EPOCH again instead of SDE_FILE, now that they're guaranteed equivalent. - test_release_date_source_date_epoch: switched to tar (base-files has S == UNPACKDIR and never gets a real SOURCE_DATE_EPOCH). - Added test_release_date_omitted_for_fallback_value. v4: - Per Richard's feedback, moved releaseTime from do_create_recipe_spdx to do_create_spdx to keep the recipe-only task fetch-free. - Per Joshua's suggestion added into each downloaded source software_Package - Updated selftests accordingly. --- meta/lib/oe/spdx30_tasks.py | 22 +++++++++++++++ meta/lib/oeqa/selftest/cases/spdx.py | 41 ++++++++++++++++++++++++++++ 2 files changed, 63 insertions(+) diff --git a/meta/lib/oe/spdx30_tasks.py b/meta/lib/oe/spdx30_tasks.py index b6456a214a..dc82f21fb0 100644 --- a/meta/lib/oe/spdx30_tasks.py +++ b/meta/lib/oe/spdx30_tasks.py @@ -36,6 +36,24 @@ def set_timestamp_now(d, o, prop): delattr(o, prop) +def get_release_date(d): + """Resolve the release date to record in a package's releaseTime property. + + Uses SOURCE_DATE_EPOCH, which by this point (do_create_spdx runs after + do_unpack and do_deploy_source_date_epoch) reflects the source mtimes. + Omits the fallback value since it is not a meaningful release date. + + Returns a datetime, or None if no release date should be recorded. + """ + source_date_epoch = d.getVar("SOURCE_DATE_EPOCH") + if not source_date_epoch or source_date_epoch == d.getVar( + "SOURCE_DATE_EPOCH_FALLBACK" + ): + return None + + return datetime.fromtimestamp(int(source_date_epoch), tz=timezone.utc) + + def add_license_expression( d, objset, license_expression, license_data, search_objsets=[] ): @@ -441,6 +459,7 @@ def _enrich_source_package(d, dl, fd, file_name, primary_purpose): def add_download_files(d, objset): inputs = set() + release_date = get_release_date(d) urls = d.getVar("SRC_URI").split() fetch = bb.fetch.Fetch(urls, d) @@ -504,6 +523,9 @@ def add_download_files(d, objset): _enrich_source_package(d, dl, fd, file_name, primary_purpose) + if release_date is not None: + dl.releaseTime = release_date + if fd.method.supports_checksum(fd): for checksum_id in bb.fetch.CHECKSUM_LIST: if checksum_id not in oe.spdx30.HashAlgorithm.NAMED_INDIVIDUALS: diff --git a/meta/lib/oeqa/selftest/cases/spdx.py b/meta/lib/oeqa/selftest/cases/spdx.py index 8285189382..88c3eb6b15 100644 --- a/meta/lib/oeqa/selftest/cases/spdx.py +++ b/meta/lib/oeqa/selftest/cases/spdx.py @@ -6,6 +6,7 @@ import textwrap import hashlib +from datetime import datetime, timezone from oeqa.selftest.case import OESelftestTestCase from oeqa.utils.commands import bitbake, get_bb_var, get_bb_vars import oe.spdx30 @@ -443,3 +444,43 @@ class SPDX30Check(SPDX3CheckBase, OESelftestTestCase): r'\d', f"Version '{version}' for package '{name}' should contain digits" ) + + def test_release_date_source_date_epoch(self): + """releaseTime should be derived from SOURCE_DATE_EPOCH. + + This is recorded on the downloaded source software_Package objects + produced by do_create_spdx (not the recipe-only do_create_recipe_spdx + task), since the release date can only be known once sources are + available and SOURCE_DATE_EPOCH has been computed. + """ + # base-files has S == UNPACKDIR and never gets a real + # SOURCE_DATE_EPOCH, so use tar, which unpacks a real tarball. + objset = self.check_recipe_spdx( + "tar", + "{DEPLOY_DIR_SPDX}/{SSTATE_PKGARCH}/builds/build-tar.spdx.json", + ) + + source_date_epoch = get_bb_var("SOURCE_DATE_EPOCH", "tar") + expected = datetime.fromtimestamp(int(source_date_epoch), tz=timezone.utc) + + pkg = None + for candidate in objset.foreach_type(oe.spdx30.software_Package): + if candidate.software_downloadLocation: + pkg = candidate + break + + self.assertIsNotNone(pkg, "Unable to find downloaded source software_Package") + self.assertEqual(pkg.releaseTime, expected) + + def test_release_date_omitted_without_downloaded_source(self): + """releaseTime only applies to downloaded source packages; recipes + with only local file:// sources have none, and get no releaseTime.""" + # base-files only has file:// sources, so it has no downloaded + # source software_Package and thus no releaseTime anywhere. + objset = self.check_recipe_spdx( + "base-files", + "{DEPLOY_DIR_SPDX}/{MACHINE_ARCH}/builds/build-base-files.spdx.json", + ) + + for candidate in objset.foreach_type(oe.spdx30.software_Package): + self.assertIsNone(candidate.releaseTime)
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247087): https://lists.openembedded.org/g/openembedded-core/message/247087 Mute This Topic: https://lists.openembedded.org/mt/121543062/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
